The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versi
A vulnerability has been found in CESNET theme-cesnet up to 1.x on ownCloud and classified as problematic. Affected by t
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Member
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticate
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's pas
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated u
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Co
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverab
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentia
Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local at
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could p
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before versio
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit th
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotect
Implemented protections on AWS credentials that were not properly protected.
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authen
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing pas
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensit
Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are rec
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login crede
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previ
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.
Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certa
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage conver
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parame
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials.
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started